Intel buys Mcafee


It was announced today that Intel will buy Mcafee for over $7 billion dollars in cash. There had been rumors that HP was looking to buy Mcafee which would have been interesting to see how they would have combined the Tippingpoint and Mcaffe intrusion prevention systems. At first glance the Intel merger does seem odd until you begin to look at some of the benefits.

Intel is developing processors with AES instructions sets included. In many ways this allows Intel to provide hardware based encryption and they now own a product to directly integrate with this processor. They could also develop AV solutions running on chips which would dramatically increase the scanning speed.

If  handled correctly this could dramatically change the availability of these products. Why buy another solution if your hardware already has one.

Intel® AES-NI Impact
Testing with McAfee Endpoint Encryption* for PCs (EEPC) 6.0, encrypting a 32GB Intel® X25-E SATA SSD using the Intel® Xeon® processor 5600 series with Intel® AES-NI showed a 30% faster server SSD provisioning time compared to the prior generation processor without Intel AES-NI.
Results for the CISM

Well ISACA was not kidding when they said it takes 6-8 weeks to get the results. I received my email at 4:00pm exactly 8 weeks after taking the exam. The good news is that I passed the exam! I am now beginning the process of  verification of my work experience. ISACA says it takes 6-8 weeks for this as well and I am sure it will probably take the full 8 weeks.

Thoughts on the CISM exam

So I took the CISM exam in June 12th. I have not received the results back yet, it generally takes 6-8 weeks. The test was tough and I thought the practice database from ISACA was a good representation of the type of questions to expect. I do think though that they could reduce the number of questions from 200. There were many repetitive questions and for only 5 domains they should either add more unique questions or reduce the number.

Preparing for the CISM exam

I have decided to sit for the CISM exam. The exam is scheduled for June 12th. ISACA only offers the exam two times per year so I figured this was the best time to take it. The CISM is growing in popularity and is becoming more common in job requirements, although it is still not as popular as the CISSP. The CISM is more focused to those in management positions around Information Security and requires three years of actual management experience in Information Security.

The exam is 200 questions and you can take up to 4 hours to complete. It is considered very rigorous and at least as difficult as the CISSP. I am very excited to take this exam and will post some information in subsequent posts. More information on the CISM exam can be found below.


Symantec to purchase PGP and GuardianEdge

While not related directly to IPS it is still news worthy. Symantec announce today they are buying PGP and GuardianEdge for $370 million dollars! Symantec has somewhat languished over the last few years without alot of truly innovative security products. This now places Symantec as a major player in the encryption space. They can now compete with other companies such as Mcaffe, Sophos and Checkpoint in the encryption space.

Interesting note: Mcafee previously owned PGP and sold it. They then later purchased Safeboot and now Symantec owns PGP. I guess Mcafee should have just kept PGP. :-)


Virtual IPS vs. Virtualized IPS

Virtualization is a top priority for most organizations today. Security of these virtualized environments should also be a top priority and in the Intrusion Prevention market most vendors are developing or have developed virtual or virtualized solutions.

The terms virtual IPS and virtualized IPS have different meanings and I want to take some time to attempt to differentiate these terms. Most vendors have had virtual IPS for many years. Virtual IPS is the ability to apply different polices to certain types of traffic. This could be done using VLAN tags or physical interfaces. IBM does this using the Protection Domains feature which allows a different policy to be deployed to different VLAN’s. Mcafee does this by allowing different policies to be assigned to physical interfaces and can also support policies to be applied based no VLAN tags.

Virtualized IPS is what most of us think of today when we discuss virtualization. Virtualized IPS is an IPS appliance that runs in a virtual environment such as VmWare, Zen or Microsoft’s Hyper-V. The IPS is installed as a virtual server and can be configured so that all server to server traffic inside and outside the virtual environment can be monitored by an IPS.

It is important to be clear on these differences in terminology because not all vendors have virtualized IPS and most sales people will not know enough to properly answer the question, Do you support virtualization? Most will say yes, because they have heard their support teams talk about virtual IPS not virtualized IPS. Virtualized IPS will continue to grow in importance and eventually all the major Intrusion Prevention vendors will have these offerings. Until then do your homework and hold the vendors accountable.

